NVD Vulnerability Detail
Search Exploit, PoC
CVE-2007-4632
Summary

Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.

Publication Date Sept. 1, 2007, 8:17 a.m.
Registration Date Jan. 29, 2021, 2:19 p.m.
Last Update Oct. 26, 2018, 11:04 p.m.
CVSS2.0 : MEDIUM
Score 4.3
Vector AV:A/AC:H/Au:N/C:P/I:P/A:P
攻撃元区分(AV) 隣接
攻撃条件の複雑さ(AC)
攻撃前の認証要否(Au) 不要
機密性への影響(C)
完全性への影響(I)
可用性への影響(A)
Get all privileges. いいえ
Get user privileges いいえ
Get other privileges はい
User operation required いいえ
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:cisco:ios:12.2e:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:12.2f:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:12.2s:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List